πΌ [RDS.23] RDS instances should not use a database engine default port
- Contextual name: πΌ [RDS.23] RDS instances should not use a database engine default port
- ID:
/frameworks/aws-fsbp-v1.0.0/rds/23
- Located in: πΌ Relational Database Service (RDS)
Descriptionβ
If you use a known port to deploy an RDS cluster or instance, an attacker can
guess information about the cluster or instance. The attacker can use this
information in conjunction with other information to connect to an RDS cluster
or instance or gain additional information about your application.
When you change the port, you must also update the existing connection strings
that were used to connect to the old port. You should also check the security
group of the DB instance to ensure that it includes an ingress rule that
allows connectivity on the new port.
Similarβ
- AWS Security Hub
- Internal
Similar Sections (Give Policies To)β
Sub Sectionsβ
Section | Sub Sections | Internal Rules | Policies | Flags |
---|
Policies (1)β
Internal Rulesβ
Rule | Policies | Flags |
---|
βοΈ dec-x-fd0bfd1b | 1 | |